I had similar problem.
User db is on LDAP. After/during ssh login, though it was successful, i got "Failed to add entry for user xxx." message for all local users.
For users with ldap entry there was no such message but the password was updated (sambaPwdLastSet field changed).
To avoid this, the pam-auth-update feature must be disabled.
Edit the /etc/pam.d/common-auth file
There is a
line. The "migrate" word is to be removed.
auth optional pam_smbpass.so migrate
Requires no restart of anything, works immediately.
#auth optional pam_smbpass.so migrate
auth optional pam_smbpass.so